DATA PROTECTION NOTICE
This Data Protection Notice (“Notice”) sets out the basis which Wong’s Plastic Surgery Centre Pte Ltd (“we”, “us”, or “our”) may collect, use, disclose or otherwise process personal data of our patients in accordance with the Personal Data Protection Act (“PDPA”). This Notice applies to personal data in our possession or under our control, including personal data in the possession of organisations which we have engaged to collect, use, disclose or process personal data for our purposes.
- As used in this Notice:“patient” means an individual who (a) has contacted us through any means to find out more about any services / treatment we provide, or (b) may, or has, entered into a contract with us for the supply of services / treatment by us; and “personal data” means data, whether true or not, about a patient who can be identified: (a) from that data; or (b) from that data and other information to which we have or are likely to have access.
- Depending on the nature of your interaction with us, some examples of personal data which we may collect from you include name, identification numbers such as NRIC, FIN, Work Permit and birth certificate, residential address, email address, telephone number, nationality, gender, date of birth, marital status, employment information, patient history, allergy information and any other medical and health records.
- Other terms used in this Notice shall have the meanings given to them in the PDPA (where the context so permits).
COLLECTION, USE AND DISCLOSURE OF PERSONAL DATA
- We generally do not collect your personal data unless (a) it is provided to us voluntarily by you directly or via a third party who has been duly authorized by you to disclose your personal data to us (your “authorized representative”) after (i) you (or your authorized representative) have been notified of the purposes for which the data is collected, and (ii) you (or your authorized representative) have provided written consent to the collection and usage of your personal data for those purposes, or (b) collection and use of personal data without consent is permitted or required by the PDPA or other laws. We shall seek your consent before collecting any additional personal data and before using your personal data for a purpose which has not been notified to you (except where permitted or authorized by law).
- We may collect and use your personal data for any or all of the following purposes:
– processing appointments, bookings, admissions, transfers / referral ;
– processing and collecting payment for products, treatment and services;
– creation, storage, hosting, backup (whether for disaster recovery or other purposes) of medical records and financial and other business records;
– verifying identity and conducting screenings, due diligence checks
– responding to queries or feedback;
– addressing or investigating complaints, claims or disputes;
– compliance with internal policies, procedures and directives;
– enforcing obligations owed to us; and/or
– complying with our legal obligations and requirements.
- We may disclose your personal data:
– the doctors and other healthcare professionals who treat or have treated you, and their respective staff;
– the Central Provident Fund Board of Singapore and/or your health insurance provider, for payment processing purposes;
– third parties that you have used to obtain or request our products and services, including referral agencies, business introducers, travel agencies or similar service providers;
– national registers and databases for various medical conditions, diseases and transplants, where such disclosure is required or permitted by law;
– accreditation or representative bodies for health care providers, agencies, facilities or healthcare professionals, where such disclosure is required or permitted by law; and/or
– anyone involved in your care or payment for your care (including a family member, friend or your caregiver or care-giving organisation) and anyone you have authorized us to contact or communicate with.
- We may also collect, use and disclose personal data where required or permitted by law for any purpose.
ACCESS TO AND CORRECTION OF PERSONAL DATA
- If you wish to make (a) an access request for access to a copy of the personal data which we hold about you or information about the ways in which we use or disclose your personal data, or (b) a correction request to correct or update any of your personal data which we hold about you, you may submit your request in writing or via email to our Data Protection Officer at the contact details provided below.
- We will respond to your request as soon as reasonably possible. In general, our response will be within three (3) business days. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA).
PROTECTION OF PERSONAL DATA
- To safeguard your personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks, we have introduced appropriate administrative, physical and technical measures such as up-to-date antivirus protection, encryption, and disclosing personal data both internally and to our authorized third party service providers and agents only on a need-to-know basis.
- You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.
ACCURACY OF PERSONAL DATA
- We generally rely on personal data provided by you (or your authorized representative). In order to ensure that your personal data is current, complete and accurate, please update us if there are changes to your personal data by informing our Data Protection Officer in writing or via email at the contact details provided below.
RETENTION OF PERSONAL DATA
- We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected, or as required or permitted by applicable laws.
- We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal or business purposes.